Elektrine lite

← Feed

@jik@federate.social

2026-09-20 17:30 UTC

There's this thing I'm seeing more and more websites doing, where if you were previously logged in and you revisit the site after the login timeout has elapsed, it briefly flashes the logged-in page, including content that should only be visible to you when you're logged in, before logging you out and taking you back to the login page. Wow, what an anti-pattern. If my login has timed out I obviously shouldn't be able to see private data for even a fraction of a second. #infosec 1/2

Replies (1)

  • @rtificial@infosec.exchange 2026-09-20 22:17

    @jik@federate.social @rk@mastodon.well.com I’ve seen this in various forms quite often. If you use a proxy tool like burpsuite you can usually step by step walk an app loading and see some wild stuff or just bypass it altogether. (Looking at you ArcGIS) But it usually some backwards flow of how auth is handled, where they SHOULD check first before loading and not checking midway or after loading a page or api.

    Open ##4785818